A new wave of cyberattacks is targeting employees searching for payroll portals via Google, leading to salary hijacking through fake websites, mobile phishing traps, and compromised home routers. These attacks are sophisticated and stealthy, exploiting recent data leaks to create highly personalized scams. A novel technique called 'Browser-in-the-Middle' attack has emerged, allowing hackers to intercept user sessions by tricking victims into entering credentials on a malicious browser interface, effectively bypassing multi-factor authentication (MFA). Additionally, attackers are purchasing live access to corporate services such as Microsoft 365, AWS, and Slack without needing passwords or MFA, based on analysis of over 20 million stealer logs by cybersecurity firm Flare. These developments mark a shift from traditional password theft to session hijacking, posing new challenges for cybersecurity defenses.
🚨 Session hijacking just replaced password theft. Attackers now buy live access to Microsoft 365, AWS, Slack—no passwords, no MFA needed. Flare analyzed 20M+ stealer logs. What they found changes everything. 👉 How fast it happens—and how to stop it: https://t.co/qrQPmwZIfK https://t.co/IEzZucM6Cp
⚠️ You passed MFA. But your session didn’t. A new attack, Browser-in-the-Middle, tricks users into typing passwords on a hacker’s browser—without knowing it. It’s fast, invisible, and bypasses MFA. Learn how it works—and how to stop it before it hits you. 👇 https://t.co/VKegS29iOx
How 'Browser-in-the-Middle' Attacks Steal Sessions in Seconds: https://t.co/PeSB9D9Sih by The Hacker News #infosec #cybersecurity #technology #news